Flask is called a \u201cmicro-framework\u201d because the idea to keep the core
simple but extensible. There is no database abstraction layer, no form
validation or anything else where different libraries already exist
that can handle that. However Flask knows the concept of extensions
that can add this functionality into your application as if it was
implemented in Flask itself. There are currently extensions for object
relational mappers, form validation, upload handling, various open
authentication technologies and more.
Update Information:
Update to 3.1.2
* Sun Aug 31 2025 Franti\u0161ek Zatloukal
[ 1 ] Bug #2366240 - CVE-2025-47278 python-flask: Flask Session Signing Fallback Key Vulnerability [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2366240
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-55e69c9cea' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
Get the latest Linux and open source security news straight to your inbox.